Skip to content

One post costs (retries + 1) squared requests, because csrf nests one retry loop inside another #491

Description

@morphqdd

post builds its body as params.merge('_csrf' => csrf) inside its own attempt block (lib/baza-rb.rb:744), and csrf is itself a get, which opens a second attempt loop (:546).

What happens: when /csrf is unreachable the inner loop burns @retries + 1 attempts and raises, then the outer loop re-runs the body construction and starts the inner loop again. retries: N costs (N + 1) squared requests.

retries:1 -> 4 GET /csrf attempts in 1.5s (BazaRb::TimedOut)
retries:2 -> 9 GET /csrf attempts in 5.4s (BazaRb::TimedOut)
retries:5 -> 36 GET /csrf attempts in 23.7s (BazaRb::TimedOut)

With the default retries: 5 one transfer fires 36 requests at /csrf and blocks for about 24 seconds. This is not a request to cache the token, which #361 already refused because the live server treats it as single use; the token still has to be fetched per attempt, only the nesting is wrong.

What should happen: the CSRF fetch should sit outside the POST's own retry region, so retries: N means at most N + 1 attempts in total.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions